Below is my CSV Data :
Company, Model,Year
Honda, Civic, 2016
Toyota, Camry, 2017
Honda, Accord, 2016
Honda, Civic SE,2017
Honda, Fit, 2017
Honda, Fit EV, 2017
Toyota, Corolla, 2016
The fields auto extracted by splunk are Company,Model and Year.
When i make a "chart count over Company by Year | addtotals " and change to statistics table in Splunk simple xml Dashboard visualizations,i get the result as
My requirement is to get the totals field as second column.
Expected:
IF not possible through the above way,kindly suggest a way to achieve the expected stats table,with total field as second column.
Thanks in Advance
Try this: chart count over Company by Year | addtotals | fields Company, Total, *
Try this: chart count over Company by Year | addtotals | fields Company, Total, *
Worked like a charm....
Thanks Ssievert